Service
Security decided in discovery, not before launch.
Threat modelling, access design, data protection and incident readiness built into the systems Kerah delivers — as engineering decisions taken at the start, not as a review carried out once the system is already shaped.
Who this is for
- Security and privacy leads assessing a supplier before production access
- Organizations holding personal, health or financial records under a legal duty
- Buyers whose own procurement requires a documented data-protection position
- Teams that must answer a regulator or an auditor about a system they did not design
The problems this addresses
- A security questionnaire arriving after the architecture is already committed
- An access model that grants far more than any role actually needs, because it was inherited from a framework default
- Personal data spread across logs, exports, tickets and backups with no inventory of where it went
- Retention written in a policy that no system enforces and nobody executes
- No agreed answer to who is called, and what they do, when something goes wrong at two in the morning
What changes
- The permission model in the system matches the authority model in the organization
- Every category of personal data has a stated purpose, location, retention period and deletion route
- An incident has a defined detection, escalation, containment and notification path before it happens
- The assessment documentation exists as a by-product of delivery rather than a project of its own
What Kerah can deliver
Capability, not a claim of past work. Final scope is established through discovery.
- Threat modelling against the system's actual data and actors
- Identity, role and permission design, including delegation and break-glass
- Data inventory, classification, retention and deletion design
- Encryption and key-management design in transit and at rest
- Audit logging designed around the questions the organization will be asked
- Data protection impact assessment support
- Secure development practice, dependency and vulnerability handling
- Incident response design, tabletop exercise and escalation definition
- Completion of buyer security and privacy questionnaires
What you receive
Artefacts, not activities. Each one is something you can hold, read or run after the engagement.
- Threat model
- Architecture and data-flow documentation
- Access and permission model
- Data inventory and retention schedule
- Encryption and key-management design
- Audit logging specification
- Data protection impact assessment input
- Incident response and escalation plan
- Security and privacy questionnaire responses
How the engagement runs
- Model the threat before choosing the control
- Controls chosen from a checklist protect against a generic system. The work starts from who would want this data, what they could reach, and what it would cost the organization.
- Design deletion at the same time as storage
- Retention that was never designed cannot be executed, particularly in backups and logs. Where data goes and how it leaves are one decision, taken together.
- Documentation as delivery output
- The data-flow diagram, access model and inventory are produced because the build needs them. That they also answer an assessor's questions is a consequence, not a separate exercise.
Commercial shape. Runs across every phase of a delivery engagement rather than as a separate project, and can also be scoped as a review of a system Kerah did not build.
Raised from the start, not before launch
Architecture, security and data decisions that are cheap to make early and expensive to retrofit.
How Kerah approaches security- Whether health, financial or other special-category data requires a separate data class, environment and access model
- Which region data must remain in, and whether every service in the architecture is available there
- Whether an AI service in the design would receive data it must never receive
- How a deletion request is executed across primary storage, replicas, exports, logs and backups
- What the buyer's own security policy requires of a supplier, and whether it is achievable
Where this stops
- This is security and privacy engineering within systems Kerah designs and builds. It is not a standalone regulated cybersecurity consultancy service, a penetration-testing practice or a managed security operations centre.
- Kerah does not certify, audit or attest to any organization's compliance, and holds no certification of its own — see the Trust Center for the current position.
- Independent penetration testing is commissioned from a specialist third party. Kerah scopes it and remediates findings; it does not mark its own work.
- Kerah does not act as an organization's data protection officer or compliance function.
Other services
Discovery and Architecture
A documented blueprint with a target architecture, a permission and data-role map, a phased roadmap and a scope you can approve, price or decline on evidence.
Enterprise Systems
One operational system where work is assigned, decisions are recorded, permissions are explicit and reporting comes from the same data people work in.
Digital Product Engineering
A designed, accessible product with a secure back end, built around the tasks people actually perform and measured after release.
Cloud, Data and Integrations
Defined interfaces, a documented data model and monitored flows, so information moves once and reporting can be trusted.
AI and Intelligent Automation
A bounded use case with defined success criteria, evaluation against representative cases, human review where it matters, and a fallback when the model is unavailable.
Managed Evolution
A defined support and release model with security maintenance, an owned backlog and a roadmap reviewed on a set cadence.
Quality, Testing and Accessibility
A system tested in both languages by people who read both, measured against WCAG 2.2 AA, and exercised under realistic load and failure conditions before launch rather than after it.
Discuss a security and privacy review.
Tell us what is not working today, who it affects and what a better outcome would change.